First published: Wed Nov 22 2017(Updated: )
The Bastet Driver of Nova 2 Plus,Nova 2 Huawei smart phones with software of Versions earlier than BAC-AL00C00B173,Versions earlier than PIC-AL00C00B173 has a use after free (UAF) vulnerability. An attacker can convince a user to install a malicious application which has a high privilege to exploit this vulnerability, Successful exploitation may cause arbitrary code execution.
Credit: psirt@huawei.com
Affected Software | Affected Version | How to fix |
---|---|---|
Huawei Nova 2 Firmware | <pic-al00c00b173 | |
Huawei Nova 2 | ||
Huawei Nova 2 Plus Firmware | <bac-al00c00b173 | |
Huawei Nova 2 Plus |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-8203 is high with a severity value of 7.8.
The Bastet Driver of Nova 2 Plus and Nova 2 Huawei smart phones with software versions earlier than BAC-AL00C00B173 and PIC-AL00C00B173 are affected.
CVE-2017-8203 is a use after free (UAF) vulnerability in the Bastet Driver of Nova 2 Plus and Nova 2 Huawei smart phones.
An attacker can exploit CVE-2017-8203 by convincing a user to install a malicious application with high privilege.
No, Huawei Nova 2 and Nova 2 Plus smartphones are not vulnerable to CVE-2017-8203.